A Northeastern University and Consumer Reports study tested 21 vehicles and 30 companion apps to examine connected-car privacy. Nineteen vehicles contacted third parties over Wi-Fi, and seven apps sent sensitive identifiers to advertising or tracking companies. Those are separate findings: a network destination does not reveal the contents of an encrypted message.
The study appeared in tech coverage on September 29, but its measurements were collected between October 2024 and August 2025. It is evidence about the tested configurations during that period, rather than a fresh scan of every current car or app.
The vehicle and phone expose different evidence
Researchers captured vehicle traffic through a controlled Wi-Fi access point. Encryption prevented them from reading the vehicle payloads. They could still observe destinations and communication patterns. For the companion apps, an instrumented phone setup allowed decrypted traffic inspection.
That difference changes what a headline can claim. Contact with an advertising-associated domain establishes a relationship worth examining. It does not establish that a particular location record, phone number or vehicle identifier was inside that vehicle’s message. The app findings provide a stronger basis for claims about transmitted identifiers.
The full paper explains the measurement setup and the disclosure process. It is scheduled for the October 2026 ACM Internet Measurement Conference. Reading its scope is essential before applying its result to another market or software version.
Encryption protects transit, not the recipient’s choices
An encrypted connection can keep a network observer from reading its contents. Once the intended recipient receives and decrypts the message, transport encryption does not determine how that recipient uses it. That is why an encrypted system can still present a privacy problem.
Consider a companion app that needs a location to find a nearby charger. The useful product question is which party needs that location, at what precision, for how long, and for which operation. Sending data required for a requested feature and retaining it for another purpose are different decisions. A permissions prompt alone does not explain the whole chain.
The sample cannot rank every brand or country
The researchers studied US-market vehicles. Their overview warns against generalizing beyond the sample, and notes that vehicles from the same manufacturer can behave differently. Honda changed one precise-location sharing practice after disclosure, according to the team. The evidence therefore includes both observed behavior and a subsequent response.
An Indian owner should not infer that a locally sold trim uses the same app, backend or consent terms as its US counterpart. Those details need checking. A current assessment would also need the app version and vehicle software version.
Follow the data through four separate questions
An owner can make the study useful without guessing what an encrypted packet contains. Start with the feature: remote unlocking, locating a parked vehicle or finding a charger. Then ask what identifier or location it needs, which recipient receives it, how that recipient uses it and which control changes the behavior. The answer should connect a setting to a specific data flow.
| Observation | What it supports | What remains unknown |
|---|---|---|
| Vehicle contacts a third-party domain | A network destination was observed | Contents of the encrypted payload |
| Decrypted app traffic includes an identifier | That identifier was transmitted in the tested setup | All later uses and retention by the recipient |
| An owner changes a phone permission | One phone-level source is constrained | Vehicle collection and server deletion |
| A manufacturer changes a disclosed practice | That specific response was reported | Every current model, region and app version |
This separates several controls that are easy to conflate. Removing an app’s location permission changes what the phone can provide through that permission. It does not establish that the vehicle has stopped collecting location, or that a server has deleted previously stored records. Uninstalling the app similarly does not demonstrate account deletion. Confirm those outcomes through the relevant service’s documented controls or a specific manufacturer response.
Ask a question the manufacturer can actually answer
A useful request might be: “For the parked-car locator on this model and app version, which recipient gets precise location, is it retained after the feature runs, and which setting stops that transfer?” Include the market, model year, app version and service name. Ask separately whether disabling the feature affects remote access or other functions you rely on.
Avoid a blanket promise that one toggle makes a connected vehicle private. Phone permissions, vehicle connectivity, account settings and backend retention are different points in the system. A setting can be worthwhile while controlling only one of them. Document the trade-off before changing a service you need, and verify the resulting behavior where the product makes it observable.
A patch and a privacy control solve different problems
In EyesTech’s Firefox 157 update guide, the action is to run the version that fixes the listed security faults. Here, the key question is which intended recipients obtain data and for what purpose. Transport encryption and software maintenance remain valuable, but neither supplies the missing recipient and retention answers.
The study makes the app an especially useful place to begin that investigation because its decrypted traffic offered stronger evidence about transmitted identifiers. Its vehicle observations identify destinations worth examining. Keeping those evidence levels separate produces a more defensible privacy assessment than labeling every observed connection a proven transfer of location.
Review the app as well as the car
Owners can inspect companion-app permissions, optional services and account controls, then identify which features would be lost by changing them. Ask the manufacturer for recipients, purposes, retention and deletion options tied to the relevant service. Keep the answers specific enough to compare with actual settings.
The study’s strongest contribution is visibility into two connected devices and two different kinds of evidence. Preserve that distinction when evaluating its privacy findings.
